Tuesday, March 28, 2006

Latest threat - SpywareQuake

SpywareQuake is appropriately named - it masquerades as spyware removal software but it is actually spyware installing software.

When it starts up it lists 33 "threats" it pretends to have found on your system.



Update: If you have a SpywareQuake infection, or another of the SmitFraud variations (including SpyAxe, SpyFalcon and SpywareStrike), excellent and easy to follow removal instructions are available here at Castle CopsWiki.




I downloaded and installed the program from the spywarequake web site, and while it gives false indications of infection, it appears to be harmless in this form. It did change the security settings in Internet Explorer, but it actually increased the security, not the other way around. A standard uninstall from the control panel's 'Add / Remove Programs' seemed to remove the program completely.

On Spyware Confidential, Suzi Turner mentions the presence of a file in the Windows/System32 folder as stickrep.dll, but no such file is present with the installation I did. This leads me to believe that rogue affiliates are probably actually to blame for the additional spyware infections. I'm off now to find a "drive-by" installation to see what the differences are.

In the mean-time, stay clear of this program - you really don't need it. If you believe you are infected, update your anti-spyware application, or manually remove it with these instructions courtesy of Adam Thomas from Sunbelt Software. There is also a blog entry on the SunbeltBLOG.

No comments: